← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
65500ac2 Firmware
5500nac2 Firmware5500nac Firmware+3 more
Jun 17, 2026
Jan 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller -...Show more
A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Versions prior to V1.10.0), Clipsal C-Bus Network Automation Controller - 5500NAC (Versions prior to V1.10.0), Clipsal Wiser for C-Bus Automation Controller - 5500SHAC (Versions prior to V1.10.0), SpaceLogic C-Bus Network Automation Controller - 5500NAC2 (Versions prior to V1.10.0), SpaceLogic C-Bus Application Controller - 5500AC2 (Versions prior to V1.10.0)Show less
1Publify Project
1Publify
Jun 17, 2026
Jan 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.
1Froxlor
1Froxlor
Jun 17, 2026
Jan 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Jan 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
1Kiwitcms
1Kiwi Tcms
Jun 17, 2026
Jan 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to gu...Show more
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is resolved by providing defaults for the `AUTH_PASSWORD_VALIDATORS` configuration setting. As of version 11.7, the password can’t be too similar to other personal information, must contain at least 10 characters, can’t be a commonly used password, and can’t be entirely numeric. As a workaround, an administrator may reset all passwords in Kiwi TCMS if they think a weak password may have been chosen. Show less
1Zed 3
1Voip Simplicity Asg
Jun 17, 2026
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.
1Zkteco
1Zktime
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
1Lazy Mouse Project
1Lazy Mouse
Jun 17, 2026
Dec 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:...Show more
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HShow less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Dec 1, 2022
N/A· v4
2.7 LOW· v3
N/A· v2
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited Do...Show more
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11, 24.0.7, and 25.0.0 contain a fix for the issue. As a workaround, don't create user accounts with long passwords.Show less
1Siyucms
1Siyucms
Jun 17, 2026
Nov 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulne...Show more
Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can be used by attackers to gain server privilegesShow less
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Oct 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
1Ikus Soft
1Rdiffweb
Jun 17, 2026
Oct 6, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
1Ikus Soft
1Rdiffweb
Jun 17, 2026
Sep 29, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.
1Ikus Soft
1Minarca
Jun 17, 2026
Sep 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
1Ikus Soft
1Rdiffweb
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
1Hcltech
2Domino
Hcl Inotes
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
1Iocoder
1Ruoyi Vue Pro
Jun 17, 2026
Aug 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
1Tabit
1Tabit
Jun 17, 2026
Aug 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: A...Show more
Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: API4 - Rate limiting.Show less
1Notrinos
1Notrinoserp
Jun 17, 2026
Aug 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
1Mealie
1Mealie
Jun 17, 2026
Aug 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.